Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

PHP 5.6.x < 5.6.12 Multiple DoS

High

Synopsis

The remote web server uses a version of PHP that is affected by multiple vulnerabilities.

Description

Versions of PHP 5.6.x earlier than 5.6.12 are vulnerable to the following issues :

- A flaw exists in the file 'gd.c' due to the improper handling of images with large negative coordinates by the imagefilltoborder() function. An attacker can exploit this to cause a stack overflow, thus crashing an application using PHP. (OSVDB 125857) - A flaw exists in the file 'php_odbc.c' when the odbc_fetch_array() function handles columns that are defined as NVARCHAR(MAX). An attacker can exploit this to crash an application using PHP. (OSVDB 125858)

Solution

Upgrade to PHP version 5.6.12 or later.